For AI agents: the complete documentation index is available at https://docs.ovhcloud.com/fr/llms.txt, the full documentation bundle is available at https://docs.ovhcloud.com/fr/llms-full.txt, and this page is available as Markdown at https://docs.ovhcloud.com/fr/guides/public-cloud/containers-orchestration/managed-private-registry/sign-artifacts-with-cosign.md.

Signer des artefacts OCI avec Cosign sur OVHcloud Managed Private Registry

Voir en Markdown

Découvrez comment signer des artefacts OCI avec Cosign sur OVHcloud Managed Private Registry

Objectif

Le service OVHcloud Managed Private Registry, un registre cloud-native basé sur Harbor, vous permet de stocker, gérer et consulter vos images de conteneurs (artefacts OCI) et vos charts Helm.

La sécurité est un sujet important : grâce à la signature des artefacts et à la vérification des signatures, vous pouvez renforcer la sécurité de vos OVHcloud Managed Private Registry en vérifiant l'intégrité d'un artefact.

Depuis la version 2.5, Harbor prend en charge Cosign, une solution de signature et de vérification d'artefacts OCI (Open Container Initiative) qui fait partie du projet Sigstore.

Info

Harbor a entamé la dépréciation de Notary dans Harbor 2.6. Notary sera supprimé dans Harbor v2.8 : vous devez donc utiliser Cosign pour signer vos images de conteneurs et vos charts Helm.

Comparé à Notary, Cosign est très simple à utiliser et présente l'avantage de permettre l'usage des capacités de réplication de Harbor pour répliquer les signatures avec l'artefact signé associé.

Ce guide explique comment signer des artefacts avec Cosign dans un service OVHcloud Managed Private Registry.

Prérequis

  • Un OVHcloud Managed Private Registry
  • L'URL et l'identifiant/mot de passe de votre registre privé
  • Une image stockée dans votre registre

Ce tutoriel suppose que vous disposez déjà d'un OVHcloud Managed Private Registry opérationnel et que vous avez suivi les guides Creating a private registry, Connecting to the UI, Managing users and projects et Creating and using private images.

Vous devez également disposer d'un Private Registry en version 2.5 minimum, avec une image stockée et un accès à votre registre privé.

Image Docker dans OVHcloud Managed Private Registry

En pratique

Installer la CLI Cosign

Vous pouvez installer la CLI Cosign sur votre ordinateur depuis les binaires, un paquet rpm, HomeBrew, ou même l'utiliser directement dans une Github Action.

Pour ce tutoriel, vous allez l'installer via HomeBrew :

brew install cosign

Vérifiez que Cosign est bien installé sur votre machine :

cosign version

Le résultat doit ressembler à ceci :

$ cosign version
  ______   ______        _______. __    _______ .__   __.
 /      | /  __  \      /       ||  |  /  _____||  \ |  |
|  ,----'|  |  |  |    |   (----`|  | |  |  __  |   \|  |
|  |     |  |  |  |     \   \    |  | |  | |_ | |  . `  |
|  `----.|  `--'  | .----)   |   |  | |  |__| | |  |\   |
 \______| \______/  |_______/    |__|  \______| |__| \__|
cosign: A tool for Container Signing, Verification and Storage in an OCI registry.

GitVersion:    2.1.1
GitCommit:     baf97ccb4926ed09c8f204b537dc0ee77b60d043
GitTreeState:  "clean"
BuildDate:     2023-06-27T06:57:11Z
GoVersion:     go1.20.5
Compiler:      gc
Platform:      darwin/arm64

Générer une clé privée

Cosign permet de générer une clé privée que vous pourrez utiliser ensuite pour signer vos images. Un mot de passe vous sera demandé de manière interactive.

Générez une clé privée :

cosign generate-key-pair

Le résultat doit ressembler à ceci :

$ cosign generate-key-pair
Enter password for private key: 
Enter password for private key again: 
Private key written to cosign.key
Public key written to cosign.pub
Info

Dans ce guide, la clé privée est générée en local. En environnement de production, vous pouvez évidemment générer la clé privée et la stocker dans un gestionnaire de clés, par exemple un Vault ou un KMS.

Signer votre artefact OCI (image de conteneur)

Signez votre image et poussez la signature vers votre instance OVHcloud Managed Private Registry.

cosign sign --key cosign.key `<harbor-instance>`/<project>/<image/path>:`<image-tag>`

Le résultat doit ressembler à ceci :

$ cosign sign --key cosign.key xxxxxx.c1.gra9.container-registry.ovh.net/library/hello-ovh:1.0.0
Enter password for private key: 
WARNING: Image reference xxxxxx.c1.gra9.container-registry.ovh.net/library/hello-ovh:1.0.0 uses a tag, not a digest, to identify the image to sign.
    This can lead you to sign a different image than the intended one. Please use a
    digest (example.com/ubuntu@sha256:abc123...) rather than tag
    (example.com/ubuntu:latest) for the input to cosign. The ability to refer to
    images by tag will be removed in a future release.

        The sigstore service, hosted by sigstore a Series of LF Projects, LLC, is provided pursuant to the Hosted Project Tools Terms of Use, available at https://lfprojects.org/policies/hosted-project-tools-terms-of-use/.
        Note that if your submission includes personal data associated with this signed artifact, it will be part of an immutable record.
        This may include the email address associated with the account with which you authenticate your contractual Agreement.
        This information will be used for signing this artifact and will be stored in public transparency logs and cannot be removed later, and is subject to the Immutable Record notice at https://lfprojects.org/policies/hosted-project-tools-immutable-records/.

By typing 'y', you attest that (1) you are not submitting the personal data of any other person; and (2) you understand and agree to the statement and the Agreement terms at the URLs listed above.
Are you sure you would like to continue? [y/N] y
tlog entry created with index: 30480064
Pushing signature to: xxxxxx.c1.gra9.container-registry.ovh.net/library/hello-ovh

Vérifier que l'image est signée avec Cosign

Pour vérifier que votre image est bien signée, connectez-vous à votre registre privé (dans l'interface Harbor), cliquez sur Projects, puis sur votre projet et sur votre image : une nouvelle coche verte apparaît.

Image Docker signée dans OVHcloud Managed Private Registry

Un clic sur l'icône > affiche les informations de signature cosign associées :

Signature cosign d'une image Docker dans OVHcloud Managed Private Registry

Aller plus loin

Pour une vue d'ensemble du service OVHcloud Managed Private Registry, consultez la documentation OVHcloud Managed Private Registry.

Cette page vous a-t-elle aidé ?